← All insights
AI audit evidenceJun 14, 2026Source: EU AI Act

Evidence checklist for EU AI Act readiness

Editorial cover for Evidence checklist for EU AI Act readiness, showing AI governance research and compliance operations.

EU AI Act readiness starts with classification, but it does not end there. Teams need evidence that shows how the system was assessed, what obligations apply, what controls exist, and how the organization monitors the system after launch.

The exact requirements depend on the role of the organization and the system category, but a practical evidence checklist helps teams prepare before a formal review.

System classification

Keep a record of the system purpose, users, jurisdiction, sector, affected population, provider or deployer role, model or vendor, autonomy, data categories, and deployment context. Then record the classification decision and rationale.

If the system is not considered high risk, explain why. If it may be high risk, identify the obligations that need deeper review.

Risk management record

Maintain a risk assessment that identifies foreseeable risks, affected users, severity, likelihood, mitigations, residual risk, and control owners. For agents, include risks related to tool use, excessive agency, prompt injection, and human oversight failure.

The risk record should be updated after material changes and incidents.

Technical and operational documentation

Evidence should describe how the system works at a level appropriate for review: model provider, data sources, retrieval sources, prompts, tools, intended use, limitations, evaluation approach, monitoring, and human oversight.

For vendor systems, keep vendor documentation, contracts, data-processing terms, and internal deployment configuration.

Human oversight and transparency

Document where human review is required, what reviewers see, how they intervene, and how decisions are recorded. Keep user notices, disclosure text, instructions, and escalation paths where relevant.

Post-launch monitoring

Keep logs, incidents, complaints, overrides, performance reviews, security events, and change history. A readiness file should show that governance continues after launch.

The checklist should produce a living evidence package, not a one-time folder. EU AI Act readiness is easier when classification, controls, and evidence are connected from the first review.

EU AI ActAI evidenceAI compliancereadiness checklist